Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hamit Cibo

#52067of 53,633
4.3Total CVSS
Vulnerabilities · 1
PT-2025-36114
4.3
2025-09-05
WordPress · Oceanwp Wordpress Theme · CVE-2025-8944
**Name of the Vulnerable Software and Affected Versions** OceanWP WordPress theme versions prior to 4.1.2 **Description** The OceanWP WordPress theme is susceptible to unauthorized option updates due to a missing capability check within an AJAX request handler. This allows any authenticated user, even those with limited privileges like a subscriber, to modify the `darkMod` setting. **Recommendations** Update the OceanWP WordPress theme to version 4.1.2 or later.